Financial Integrity Monitor

European Economic Area EEA

Domains (D1–D6)
5
Sources
11
Role actions
8
Horizon <90d
4
Jurisdiction profile
CleanTier ARisk: IncreasingMixed

EU AML architecture is mid-transition: AMLR (Reg 2024/1624) becomes the directly-applicable single rulebook from 10 July 2027, 6AMLD (Dir 2024/1640) is under national transposition, and AMLA (Reg 2024/1620) began operations mid-2025 in Frankfurt, building toward direct CASP/bank supervision from 2028.

MoreSanctions architecture (19th/20th Russia packages) is aggressive but BO transparency was rolled back by the 2022 Sovim ruling and CASP supervision remains nationally fragmented pending AMLR application.

Key deficiencies
  • Beneficial ownership register public access remains restricted EU-wide since the CJEU Sovim/WM ruling (Nov 2022); BORIS interconnection cannot provide public access, undermining D2 transparency
  • Bulgaria, an EU/EEA member state, remains on the FATF Jurisdictions Under Increased Monitoring ('grey') list pending on-site verification as of the June 2026 Plenary
  • No formal operational information-exchange interface exists between Europol and AMLA, fragmenting the EU financial intelligence landscape
  • Divergent national implementation of MiCA/CASP AML supervision creates 'jurisdiction shopping' risk flagged by France's AMF, Austria's FMA and Italy's CONSOB
  • AMLA direct supervision of high-risk obliged entities (including crypto) does not begin until 2028, leaving a multi-year gap during which national supervisors retain primary responsibility despite acknowledged inconsistency
Recent developments (18m)
  • AMLA began operations mid-2025 in Frankfurt; Bruna Szego appointed first Chair; staff reached ~120 by end-2025
  • European Commission added Russia to the EU list of high-risk third countries for AML/CFT (Delegated Regulation (EU) 2026/46, 3 Dec 2025)
  • EU 19th sanctions package (23 Oct 2025) sanctioned the A7A5 ruble-backed stablecoin ecosystem, its developer, Kyrgyz issuer and trading platform, plus five additional Russian banks and third-country banks/oil traders
  • EU 20th sanctions package (23 Apr 2026, crypto provisions effective 24 May 2026) imposed a sector-wide transaction ban on Russian- and Belarusian-established crypto-asset service providers and activated the anti-circumvention tool against an entire jurisdiction for the first time
  • EBA's fifth biennial ML/TF risk assessment flagged a 2.5-fold increase in authorised CASPs in the EU between 2022 and 2024 alongside persistent AML/CFT control weaknesses
  • FATF June 2026 Plenary made an initial determination that Bulgaria has substantially completed its action plan, pending an on-site verification visit before delisting
Weekly brief

Lead signal

Lead Signal

Read full brief

Lead Signal

Two structural developments define this cycle for the EEA financial-integrity picture. First, the EU Anti-Money-Laundering Package continued to move on schedule: the AML Regulation (AMLR, Regulation (EU) 2024/1624) remains fixed to apply directly across all 27 Member States from 10 July 2027, without national transposition, retaining its harmonised 25 percent beneficial-ownership threshold, while the sixth Anti-Money-Laundering Directive (6AMLD) confirmed the same 10 July 2027 transposition deadline, with registry-access provisions phased through to 2029. The Anti-Money-Laundering Authority (AMLA, Regulation (EU) 2024/1620) passed its first regulatory-technical-standards deadline on 10 July 2026 and published a final report on 21 July 2026 addressing cooperation arrangements for direct supervision, ahead of a January 2028 go-live at which roughly 40 selected cross-border obliged entities move under the AMLA direct-supervision perimeter. Second, the EU sanctions architecture against Russia escalated further, with the 21st sanctions package (adopted 23 July 2026) extending designation criteria for the first time beyond vessels themselves to the enabling service layer around the shadow fleet: bunkering providers, crewing agencies, and ship-registry facilitators. This follows the 20th package earlier move, effective 24 May 2026, to impose a total EU-operator transaction ban on Russia-based crypto-asset service providers, naming the RUBx platform and prohibiting EU assistance to the Russian digital rouble, alongside the designation of a Kyrgyz exchange facilitating the A7A5 stablecoin. Read together, these two currents show sanctions-evasion infrastructure and AML supervisory architecture both migrating toward more granular, structurally-targeted instruments rather than incident-level designations.

Other Developments

MiCA transitional window closed. The Markets in Crypto-Assets Regulation reached full enforcement across all 27 Member States on 1 July 2026 as its grandfathering period expired. Eight MiCA-compliant euro-denominated stablecoins were recorded as of June 2026, up from five, with compliant market capitalisation up 128 percent year-on-year to approximately 673.9 million dollars; Circle EURC remains the dominant issuer by outstanding value even as its relative market share is reported to be declining against newer entrants.

FATF grey-list churn continues. The June 2026 plenary added Iraq and Bosnia and Herzegovina to the list of jurisdictions under increased monitoring and removed Algeria and Namibia, netting the list to 22 jurisdictions; the black list was unchanged. Laos remained grey-listed, with FATF citing continuing deficiencies in Special Economic Zone casino and bank supervision, financial-intelligence-unit capacity, and money-laundering prosecution, concerns that sustain long-standing attention on the Golden Triangle Special Economic Zone 99-year concession enclave. In a related signal outside the FATF process itself, the National Bank of Cambodia governor publicly warned in January 2026 that scam-centre and illegal online-gambling activity risks re-listing, three years after the country February 2023 removal from the grey list.

Gold-trade laundering exposure persists in the UAE. Despite an April 2026 guidance refresh from the Central Bank of the UAE, gold and precious-metals trade continues to present structural trade-based-money-laundering exposure through over- and under-invoicing, allowing illicit gold proceeds to be laundered without the funds leaving the jurisdiction.

Conflict-finance designations continued on two fronts. The U.S. Treasury Office of Foreign Assets Control designated additional Houthi, Ansarallah, smuggling and revenue facilitators across Yemen, Oman and the UAE on 16 January 2026, sustaining a petroleum-import-taxation architecture assessed to generate hundreds of millions of dollars annually. Separately, FinCEN issued a supplemental alert on 30 June 2026 addressing fiscal fuel-smuggling and tax-evasion schemes on the US-Mexico border linked to the Cartel de Jalisco Nueva Generacion, a corridor assessed to generate tens of billions of dollars annually, with parallel OFAC action against two individuals and nine entities.

Cross-Monitor Connections

The service-layer expansion of EU sanctions designations, reaching bunkering, crewing and ship-registry facilitators rather than vessels alone, intersects directly with commodity-flow and conflict-finance tracking relevant elsewhere in the fleet: a shadow-fleet enabler designated for sanctions purposes is simultaneously a node in physical commodity-flow integrity. The EU crypto-transaction ban on Russia-based service providers and the parallel designation of an exchange facilitating the A7A5 stablecoin sit at the boundary between sanctions architecture and digital-asset market structure, and connect to conflict-finance tracking insofar as sanctioned-jurisdiction actors migrate settlement onto stablecoin rails as fiat channels close. The Houthi and CJNG designations both illustrate revenue architectures, petroleum-tax extraction and fiscal fuel-smuggling respectively, that generate financing at a scale relevant to conflict-finance and extractive-industry-integrity tracking beyond financial-integrity own AML/CTF lens.

Outlook

The near-term calendar is dominated by AMLA build-out: further RTS and ITS packages are expected through 2026 and into 2027 as the Authority stands up the joint-supervisory-team methodology it will need for January 2028 direct supervision of roughly 40 entities, a governance model the sector has not previously operated under. The 10 July 2027 date remains the pivotal fixed point for both AMLR direct application and 6AMLD transposition deadline, though the transposition status of individual Member States is not yet established and remains a tracked gap. On sanctions, the trajectory of designation criteria toward enabling-service layers and crypto rails is assessed to continue, and the interaction between MiCA now-fully-enforced euro-stablecoin regime and sanctions-evasion migration onto digital rails is a developing area warranting continued attention. Any scenario content elsewhere in this brief is illustrative orientation only, not a prediction of designation or enforcement outcomes.

weekly_brief_draft · JID EEA
Domain intelligence (D1–D6)

D1 Sanctions Architecture and Evasion

Sanctions Architecture and Evasion

Continue reading

The Council of the European Union adopted its 21st Russia sanctions package on 23 July 2026 under Council Regulation (EU) No 269/2014, adding 48 individuals and 168 entities to the EU restrictive-measures list. The scale of this listing action is itself a continuity signal, corroborated at Tier 1 through the Council own press release and independently cross-checked against four separate law-firm client alerts: the EU designation cadence against Russia-linked targets has not slowed through more than four years of successive packages. The more analytically significant development this cycle, however, is architectural rather than numerical. Assessed-confidence reporting, sourced to Tier-4 legal commentary rather than a retrieved primary EUR-Lex or Consilium full text for this specific provision, indicates that the 21st package designation criteria were extended for the first time to reach the enabling service layer around the Russian shadow tanker fleet: bunkering suppliers, crewing agencies, and ship-registry facilitators, rather than vessels and their operators alone. If this detail is confirmed in the adopted implementing text, it represents a structural widening of the EU sanctions net from asset-level designation, a named vessel or a named company, to function-level designation, the services that keep a shadow fleet operating day to day. This logic echoes the approach seen elsewhere in this cycle crypto-asset designations, where the target is not a single sanctioned entity but the infrastructure layer enabling continued access.

That crypto dimension traces to the EU 20th sanctions package, effective 24 May 2026 under an instrument identified in secondary sourcing as Council Regulation (EU) 2026/506, which imposed a total transaction ban on EU operators dealing with Russia-based crypto-asset service providers. The package named the RUBx platform specifically and prohibited EU entities from providing any assistance toward the Russian digital rouble project, a comparatively rare instance of EU sanctions architecture reaching directly into a sanctioned state own central-bank digital currency initiative rather than only third-party financial intermediaries. In a related but jurisdictionally distinct action, a Kyrgyz-registered exchange facilitating the A7A5 stablecoin, a token that has drawn attention as a possible sanctions-evasion settlement rail, was separately designated. Both crypto-related findings this cycle carry Tier-4 secondary-source corroboration only; no primary EUR-Lex text specific to the 20th package instrument was retrieved this cycle, which caps assessed rather than high confidence for the crypto-specific elements even though the 21st package headline adoption and designation counts are independently corroborated at Tier 1.

Taken together, the picture for EEA-domiciled obliged entities is one of an EU sanctions architecture that continues to escalate not merely in the volume of designations but in the granularity of what it reaches: physical enabling services around a shadow fleet, and the digital-asset settlement rails that could substitute for closed fiat channels once conventional correspondent-banking access is denied. For banks, payment institutions, and crypto-asset service providers with correspondent or counterparty exposure to Russia-adjacent trade and settlement corridors, screening architecture built around entity-level and vessel-level designation lists needs to extend to service-provider and platform-level exposure to keep pace with this pattern. The absence, this cycle, of any identified enforcement action against a specific bunkering or crewing facilitator under the new criteria is itself worth noting under an enablement-as-signal framing: designation criteria having been extended is a different fact from designation criteria having been used, and the gap between the two is a fair subject for continued tracking.

Outlook

The near-term sanctions-architecture question for the EEA is whether the service-layer designation approach trialled in the 21st package becomes a template applied to future packages, and whether crypto-asset designations of the RUBx and A7A5 type expand to capture additional stablecoin or exchange infrastructure identified as facilitating evasion. The EU oil-price-cap update mechanism remains suspended until July 2027 on current information, a procedural point that continues to distinguish the EU autonomous listing cadence from OFAC and OFSI timing, though no head-to-head comparative sanctions action between the three regimes was identified this cycle. Firms with shadow-fleet-adjacent trade-finance or correspondent exposure, and crypto-asset service providers with any Russia-linked counterparty history, are the populations most directly implicated by this cycle architecture shift. Any scenario content elsewhere in this brief illustrating future evasion-infrastructure migration is offered for analytical orientation only and is not a prediction of designation outcomes.

D2 Beneficial Ownership and Corporate Transparency

Beneficial Ownership and Corporate Transparency

Continue reading

The European Union anti-money-laundering package rests on three distinct legal instruments, and the durable structural fact worth restating each cycle is that these are not three names for one law. The AML Regulation (AMLR, Regulation (EU) 2024/1624) is directly applicable EU law, taking effect uniformly across all 27 Member States without any national transposition step; the sixth Anti-Money-Laundering Directive (6AMLD, Directive (EU) 2024/1640) is a directive that each Member State must transpose into its own national law, preserving space for local implementation choices within a harmonised framework; and the AMLA Regulation (Regulation (EU) 2024/1620) establishes the Anti-Money-Laundering Authority itself, a new EU-level body whose direct and indirect supervision perimeter shifts the AML/CTF supervisory model away from a purely national-competent-authority structure toward a hybrid EU-level regime. This cycle, all three instruments moved on record. The AMLR application date remains fixed at 10 July 2027, retaining the harmonised 25 percent beneficial-ownership identification threshold that replaces the patchwork of Member-State-specific formulae obliged entities in non-banking professions have historically had to apply. The 6AMLD transposition deadline was confirmed for the same 10 July 2027 date, with registry-access provisions for beneficial-ownership information phased through to 2029, preserving 6AMLD as the nationally-transposed, registry-facing half of the architecture even as AMLR becomes the directly-applicable rulebook half. AMLA itself passed its first regulatory-technical-standards package deadline on 10 July 2026 and published a final report on 21 July 2026 addressing cooperation arrangements within the AML/CTF supervisory system for the purposes of direct supervision under Article 15(3) of its founding regulation. That report is a preparatory step toward January 2028, when AMLA is set to assume direct supervision of approximately 40 selected high-risk cross-border obliged entities, with a selection process beginning 1 July 2027 and administrative fines of up to 10 percent of annual turnover available to AMLA in that direct-supervision role.

This cycle carries a specific gap worth naming rather than papering over: while the bloc-wide 6AMLD transposition deadline of 10 July 2027 is confirmed, the transposition vehicle and status for any individual EEA Member State, whether a given state has already transposed, is partway through, or has not yet begun, was not established this cycle. Beneficial-ownership and corporate-transparency risk in the EEA is therefore currently better characterised at the architecture level than at the Member-State-implementation level, and the FATF grey-list churn recorded this cycle elsewhere (Iraq and Bosnia and Herzegovina added, Algeria and Namibia removed, netting the list to 22 jurisdictions) is a useful reminder that beneficial-ownership and anti-money-laundering capacity gaps are a global rather than an EEA-specific phenomenon, even as the EEA architecture itself continues to mature on a fixed and now well-corroborated timeline.

The claim substrate this cycle also flags fund-structure and high-net-worth customer typologies as directly affected by the AMLR Article 61 customer-due-diligence provisions, alongside Article 24 reporting obligations applicable to banks and cross-sector obliged entities generally. This customer-typology specificity is a useful reminder that beneficial-ownership transparency requirements bear differently on different business lines: a fund administrator handling layered fund structures faces a different practical beneficial-ownership identification challenge than a retail bank processing standard corporate account openings, even though both sit under the same AMLR rulebook from 10 July 2027.

For obliged entities, the practical implication of this cycle content is less about any single new rule and more about calendar convergence: three instruments, three distinct legal mechanisms, and effectively one pivotal date, 10 July 2027, at which the directly-applicable rulebook and the transposed directive both bite, ahead of a January 2028 date at which the largest cross-border entities additionally face a new EU-level supervisor rather than their national competent authority alone.

Outlook

The period between now and 10 July 2027 is the operative planning window for beneficial-ownership and corporate-transparency compliance programmes across the EEA: obliged entities in non-banking professions in particular face a harmonised 25 percent threshold replacing whatever Member-State-specific formula they currently apply. AMLA further RTS and ITS packages are expected through the remainder of 2026 and into 2027 as the direct-supervision selection process approaches its 1 July 2027 start; firms uncertain whether they fall within the roughly-40-entity direct-supervision perimeter have a defined, if not yet fully populated, timeline against which to assess exposure. The unresolved Member-State-by-Member-State transposition-status gap identified this cycle is worth monitoring directly, since divergent national timelines ahead of a common 2027 deadline could produce transitional inconsistency across the bloc. Any forward-looking framing here is offered as analytical orientation, not as a prediction of any specific Member State transposition outcome.

D3 Enabler Jurisdictions and Professional Facilitators

Enabler Jurisdictions and Professional Facilitators

Continue reading

The June 2026 FATF plenary added Iraq and Bosnia and Herzegovina to the list of jurisdictions under increased monitoring and removed Algeria and Namibia, netting the grey list to 22 jurisdictions with the black list unchanged. This churn is a useful backdrop against which to read two more specific enabler-jurisdiction signals this cycle. Laos remained grey-listed at the same plenary, with FATF citing continuing deficiencies in Special Economic Zone casino and bank supervision, financial-intelligence-unit capacity, and money-laundering prosecution capability. This sustains long-standing concern about the Golden Triangle Special Economic Zone, an enclave operating under a 99-year concession structure that has repeatedly surfaced in enabler-jurisdiction analysis as a governance gap distinct from the general Lao national AML framework: the concession structure itself is assessed to create a supervisory perimeter that ordinary national oversight does not straightforwardly reach.

Cambodia, though not itself grey-listed, is the second enabler-jurisdiction signal this cycle. Cambodia exited the FATF grey list in February 2023, and the National Bank of Cambodia governor issued a public warning in January 2026 that continuing scam-centre and illegal online-gambling activity risks a re-listing, three years after that removal. This is a notable instance of a jurisdiction own central bank publicly flagging re-listing risk ahead of any FATF action confirming it, which is itself an enablement-as-signal data point: the absence of confirmed FATF action to date does not indicate the absence of underlying risk, and the governor own public statement is evidence that domestic authorities assess the risk as live rather than resolved.

The third enabler-jurisdiction signal this cycle concerns the United Arab Emirates, where gold and precious-metals trade continues to present structural trade-based-money-laundering exposure through over- and under-invoicing, despite an April 2026 guidance refresh from the Central Bank of the UAE. The structural feature worth naming explicitly is that illicit gold proceeds can be laundered domestically without the underlying funds ever leaving the jurisdiction, which distinguishes this exposure from cross-border TBML corridors that depend on trade-finance documentation crossing multiple jurisdictions. This finding carries Tier-3 sourcing only, with no Tier-1 Central Bank of the UAE primary text retrieved this cycle corroborating the specific persistence-despite-guidance-refresh characterisation, though independent Tier-3 sourcing converges on the underlying exposure assessment.

Across all three signals, the common analytical thread is architecture over incident: none of Laos, Cambodia, or the UAE recorded a discrete enforcement event this cycle that would independently justify attention, yet each represents a structural condition, an enclave governance gap, a re-listing-risk warning from within the jurisdiction itself, and a persistent trade-based exposure channel, that is more informative about ongoing enabler-jurisdiction risk than any single enforcement action would be.

Outlook

The FATF October 2026 plenary is the next scheduled checkpoint at which Laos grey-list status and any further movement on Iraq, Bosnia and Herzegovina implementation of their respective action plans will next be assessed. Whether Cambodia own governor public warning translates into a formal FATF re-listing process before that plenary, or a subsequent one, is the most consequential single data point to track for Southeast Asian enabler-jurisdiction risk this year. For the UAE, the practical question is whether the April 2026 CBUAE guidance refresh produces a measurable change in gold-trade TBML typology reporting over the coming cycles, or whether the structural domestic-laundering channel persists unchanged, which would suggest the guidance refresh addressed disclosure form rather than underlying exposure. Any scenario content elsewhere in this brief illustrating enabler-jurisdiction evasion patterns is offered for analytical orientation only, not as a prediction of any jurisdiction listing status.

D4 Conflict Finance and Extractive-Industry Integrity

Conflict Finance and Extractive-Industry Integrity

Continue reading

Two designation actions this cycle sustain distinct but structurally comparable conflict-finance and illicit-revenue architectures. The U.S. Office of Foreign Assets Control designated additional Ansarallah, Houthi, smuggling and revenue facilitators across Yemen, Oman and the United Arab Emirates on 16 January 2026, sustaining a petroleum-import-taxation architecture assessed to generate hundreds of millions of dollars annually for the network. This is a Tier-1 OFAC-sourced finding, though no corroborating OFSI designation action was identified this cycle, which caps the finding at assessed rather than high confidence notwithstanding the primary-source quality of the OFAC action itself; the absence of a parallel UK action is worth tracking as a divergence point between the two sanctions regimes rather than treated as an oversight.

Separately, FinCEN issued a supplemental alert on 30 June 2026 addressing fiscal fuel-smuggling and tax-evasion schemes on the United States-Mexico border linked to the Cartel de Jalisco Nueva Generacion, a corridor assessed to generate tens of billions of dollars annually, a materially larger figure than the Houthi network estimate, reflecting the scale difference between a cartel-controlled fuel-smuggling corridor and a conflict-actor petroleum-taxation scheme. The FinCEN alert was accompanied by a parallel OFAC action against two individuals and nine entities, and this coordinated FinCEN-OFAC pairing is itself a structural point: the alert function, oriented toward prompting suspicious-activity-report filings from banks and cross-sector obliged entities under Bank Secrecy Act reporting requirements, and the designation function, oriented toward asset-freezing and transaction prohibition, are operating in tandem rather than sequentially, which is a more mature enforcement posture than either function operating alone.

Both cases illustrate the three-pillar balance principle directly: the Houthi designation sits primarily in a counter-terrorist-financing frame, revenue generation supporting a designated terrorist organisation, while the CJNG fuel-theft alert sits primarily in an anti-money-laundering frame, tax-evasion and smuggling proceeds requiring layering and integration through the financial system, even though both ultimately fund organisations capable of large-scale violence and territorial control. Neither case, notably, surfaces a direct EEA nexus this cycle; both are US-sourced findings concerning corridors and networks outside the EEA jurisdiction. Their relevance to EEA-domiciled obliged entities is indirect, through correspondent-banking and trade-finance exposure to the corridors and counterparties named, rather than through any EEA-specific enforcement action of comparable character this cycle.

Outlook

The absence of an OFSI action corroborating the January 2026 OFAC Houthi-network designation is worth monitoring directly: either a UK designation follows in a subsequent cycle, in which case the OFAC-OFSI cadence gap narrows, or it does not, in which case the divergence becomes a more durable feature of the transatlantic sanctions relationship on this specific network. For the CJNG corridor, the key forward question is whether the coordinated FinCEN-alert-plus-OFAC-designation model is extended to other fuel-smuggling or tax-evasion corridors globally, which would indicate a repeatable enforcement template rather than a one-off pairing specific to this network. EEA-domiciled banks and trade-finance providers with correspondent exposure to either corridor are the population most directly implicated, even absent a discrete EEA enforcement action this cycle. Any scenario content elsewhere in this brief illustrating conflict-finance typology patterns is offered for analytical orientation only, not as a prediction of future designation activity.

D5 Crypto, Digital Assets, and Financial Innovation

Crypto, Digital Assets, and Financial Innovation

Continue reading

The Markets in Crypto-Assets Regulation reached full enforcement across all 27 Member States on 1 July 2026 as its transitional grandfathering window closed, the single most consequential EEA digital-asset-market milestone this cycle. Eight MiCA-compliant euro-denominated stablecoins were recorded as of June 2026, up from five, with compliant market capitalisation up 128 percent year-on-year to approximately 673.9 million dollars; Circle EURC remains the dominant issuer by outstanding value even as its relative market share is reported to be declining against newer MiCA-native entrants. This finding carries Tier-4 secondary-source corroboration, consistent across independent commercial-data sources, though no direct ESMA or EBA primary text was retrieved this cycle confirming the milestone in primary-regulator language.

The more analytically significant crypto-asset development this cycle, read through a financial-innovation lens rather than a sanctions lens, is the coincidence in timing between MiCA reaching full enforcement and the EU sanctions architecture reaching directly into crypto-asset infrastructure: the 20th sanctions package, effective 24 May 2026, imposed a total transaction ban on EU operators dealing with Russia-based crypto-asset service providers, named the RUBx platform specifically, and prohibited EU assistance to the Russian digital rouble project, while a Kyrgyz exchange facilitating the A7A5 stablecoin was separately designated. Read together with the MiCA full-enforcement milestone, this cycle content suggests that EU digital-asset market regulation and EU sanctions-evasion containment strategy are converging on the same underlying infrastructure question: which entities are authorised to operate crypto-asset rails within or adjacent to the EU, and which are not. A MiCA-authorised, EU-domiciled stablecoin issuer and a sanctioned Russia-based crypto-asset service provider sit at opposite ends of the same regulatory perimeter question, one inside a compliance framework the EU is actively building out, the other affirmatively excluded from EU-facing access to that framework.

This convergence is assessed rather than confirmed: the crypto-sanctions elements carry Tier-4 secondary-source corroboration only, with no primary EUR-Lex text for the underlying 20th-package instrument retrieved this cycle, and the MiCA milestone itself similarly lacks a retrieved primary-regulator citation. The underlying direction, however, both a maturing compliant-stablecoin market and an EU sanctions architecture reaching into crypto-asset infrastructure, is corroborated across independent secondary sources for each respective finding, which supports an assessed-confidence structural reading even without a single primary source spanning both developments.

Outlook

The EBA is expected to provide further clarification on the PSD3/MiCA dual-licensing boundary for e-money-token-related activity, following its 12 February 2026 opinion narrowing that scope, though the timing of any further clarification is uncertain. Whether the euro-stablecoin issuer landscape continues to diversify away from Circle EURC dominance, or whether EURC relative share stabilises, is a market-structure question with direct relevance to sanctions-evasion-containment strategy insofar as issuer concentration affects how easily EU authorities can enforce transaction-level restrictions across the stablecoin ecosystem. Any scenario content elsewhere in this brief illustrating digital-asset sanctions-evasion typology patterns is offered for analytical orientation only, not as a prediction of any issuer market-share outcome or designation action.

D6 Compliance Technology & Active Defence

Not covered

Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.

D7 AML/CTF Regime

Not covered

AML/CTF Regime is not yet covered for this jurisdiction in this report.

Regulatory horizon
In Force Pending2026-Q3 · ±half_year

AMLA Work Programme / build-out — first RTS package and ITS report

AMLA stands up its supervisory methodology and cooperation framework ahead of direct-supervision go-live.
Adopted10 Jul 2027 · ±quarter

AMLR directly applicable; 6AMLD transposition deadline bites

The single AML rulebook (AMLR) becomes directly applicable EU law with no national transposition; 6AMLD transposition deadlines bite across Member States.
Consultation2027-Q1 · ±year

EU Supra-National Risk Assessment (SNRA) refresh (analyst estimate)

An updated SNRA would refresh the EU cross-border ML/TF risk typology baseline referenced by AMLA and national FIUs.
source not collected
Adopted2028-Q1 · ±multi_year

AMLA begins direct supervision of selected obliged entities

AMLA assumes direct supervision of approximately 40 selected high-risk cross-border obliged entities, with administrative fines up to 10 percent of annual turnover.
4 dated · 5 pending date · baseline fim-2026-07-05
Role action cards
MLROHigh

AMLA passed its first supervisory-milestone deadline while OFAC and FinCEN sustained parallel conflict-finance and cartel-finance designation activity.

The AMLA RTS/ITS milestones and the fixed 10 July 2027 AMLR/6AMLD dates set the reporting and CDD-obligation calendar MLROs need to plan around, while the Houthi and CJNG designations are live SAR-relevant typology signals for correspondent and trade-finance exposure.

5 evidence refs
ComplianceHigh

All three EU AML Package instruments and the EU sanctions architecture moved this cycle, alongside MiCA reaching full enforcement.

Compliance functions face a converging calendar of AMLR direct application, 6AMLD transposition, AMLA direct-supervision build-out, an expanded sanctions designation criteria, and a fully-enforced MiCA regime, all requiring control-framework review this cycle.

7 evidence refs
LegalAssessed

EU sanctions designation criteria expanded to the shadow-fleet service layer and to crypto-asset service providers this cycle.

Legal counsel should note the extension of designation criteria beyond entity and vessel level to enabling-service providers, and the continued OFAC designation cadence against Houthi and CJNG-linked networks, as sanctions-nexus and enforcement-trajectory signals relevant to client-instruction risk.

5 evidence refs
BoardAssessed

The EU AML Package and sanctions architecture both reached material milestones this cycle, and MiCA reached full enforcement.

At the governance level, the fixed 10 July 2027 AMLR/6AMLD date and the January 2028 AMLA direct-supervision go-live represent scheduled strategic-level regulatory change, while the sanctions escalation and MiCA milestone carry reputational and financial-crime-risk relevance for institutions with Russia-adjacent or crypto-asset exposure.

3 evidence refs
CTOAssessed

MiCA full enforcement coincided with an EU total transaction ban on Russia-based crypto-asset service providers and an exchange designation tied to the A7A5 stablecoin.

Technology functions supporting crypto-asset infrastructure should note the platform-level and stablecoin-level designation pattern this cycle as a technical-evasion-vector signal distinct from the MiCA compliance milestone itself.

2 evidence refs
RiskAssessed

Enabler-jurisdiction, conflict-finance, and sanctions-architecture signals converged this cycle around structural rather than incident-level findings.

Risk functions should read the UAE gold-trade exposure, the Laos and Cambodia enabler-jurisdiction signals, the Houthi and CJNG designations, and the sanctions service-layer expansion together as a cross-typology exposure-concentration picture warranting escalation review.

8 evidence refs
OperationsAssessed

Sanctions screening scope needs to extend to service-provider and platform-level exposure following this cycle designation-criteria expansion.

Operational screening built around entity and vessel-level lists should be reviewed against the newly-designated shadow-fleet service providers and crypto-asset platforms, and against the Houthi and CJNG-linked designations, to keep transaction-monitoring thresholds current.

4 evidence refs
AuditPossible

AMLA first supervisory-milestone deadline and the fixed AMLR/6AMLD dates create a documented control-testing horizon for beneficial-ownership programmes.

Internal audit has a defined future testing point, the 10 July 2027 AMLR/6AMLD date and the January 2028 AMLA direct-supervision go-live, against which current beneficial-ownership identification and documentation practices can be benchmarked.

3 evidence refs
Decision lens
MLRO

AMLA passed its first supervisory-milestone deadline while OFAC and FinCEN sustained parallel conflict-finance and cartel-finance designation activity.

Compliance

All three EU AML Package instruments and the EU sanctions architecture moved this cycle, alongside MiCA reaching full enforcement.

Legal

EU sanctions designation criteria expanded to the shadow-fleet service layer and to crypto-asset service providers this cycle.

Board

The EU AML Package and sanctions architecture both reached material milestones this cycle, and MiCA reached full enforcement.

CTO

MiCA full enforcement coincided with an EU total transaction ban on Russia-based crypto-asset service providers and an exchange designation tied to the A7A5 stablecoin.

Risk

Enabler-jurisdiction, conflict-finance, and sanctions-architecture signals converged this cycle around structural rather than incident-level findings.

Operations

Sanctions screening scope needs to extend to service-provider and platform-level exposure following this cycle designation-criteria expansion.

Audit

AMLA first supervisory-milestone deadline and the fixed AMLR/6AMLD dates create a documented control-testing horizon for beneficial-ownership programmes.

Shared evidence: 9 refs
Typology observations
Exposure: {'total_matched_typologies': 0, 'by_typology': {}, 'top_indicators': [], 'exposure_note': None}
Scenario sketches

AMLA Direct Supervision Transition and the Joint-Supervisory-Team Model

As AMLA moves from RTS/ITS build-out toward January 2028 direct supervision of a small set of selected cross-border obliged entities, one illustrative structural pathway is a joint-supervisory-team model in which AMLA staff and national competent authority staff jointly examine a directly-supervised group across multiple Member States simultaneously, rather than each national authority examining only its own subsidiary in isolation. Under this illustrative model, an evasion architecture built around exploiting supervisory gaps between Member States, for example routing higher-risk beneficial-ownership structures through the subsidiary supervised by the national authority assessed as lowest-capacity, would face a materially different landscape once AMLA joint examination reaches across the full corporate group rather than stopping at national borders. This is an illustrative structural sketch of how the AMLR direct-applicability, 6AMLD national-transposition, and AMLA direct-and-indirect-supervision architecture could interact operationally; it does not describe any observed AMLA examination and is not a description of a specific entity.

Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.

Standing trackers (T1–T6)
TrackerStatusNote
T1 · Russian Sanctions-Evasion Architectureescalating20th and 21st EU sanctions packages escalate designation scope into crypto (total CASP transaction ban, RUBx/A7A5) and shadow-fleet support-service layers.
T2 · EU AML Package / AMLAmaterial_changeAMLR/6AMLD both fixed at 10 July 2027; AMLA passed its first RTS deadline and published a 21 July 2026 ITS report ahead of January 2028 direct supervision.
T3 · FATF Grey ListmixedJune 2026 plenary added Iraq and Bosnia and Herzegovina, removed Algeria and Namibia, netting the grey list to 22 jurisdictions.
T4 · Beneficial-Ownership Register Statusstable6AMLD retains national BO-register responsibility, transposition due 10 July 2027 with access-provision phasing to 2029; no new interconnection go-live confirmed this cycle.
T5 · Crypto & Digital-Asset IntegrityescalatingMiCA full enforcement (1 Jul 2026) coincides with a total EU transaction ban on Russia-based crypto-asset service providers.
T6 · Sanctions Regime DivergencewatchEU autonomous listing (service-layer designation, suspended oil-price-cap update mechanism to Jul 2027) continues to diverge procedurally from OFAC/OFSI cadence; no head-to-head comparative action identified this cycle.
Registers

Enforcement actions

  • The Commission adopted Delegated Regulation (EU) 2026/46, formally listing Russia as a high-risk third country with strategic AML/CFT deficiencies, following a technical assessment triggered by Russia's suspended FATF membership. 3 Dec 2025
  • The 19th sanctions package designated the developer and Kyrgyz issuer of the ruble-backed stablecoin A7A5, the operator of a platform trading it, five additional Russian banks (Istina, Zemsky Bank, Absolut Bank, MTS Bank, Alfa-Bank), and eight banks/oil traders in Tajikistan, Kyrgyzstan, UAE and Hong Kong, alongside a full transaction ban on Rosneft and Gazprom Neft. 23 Oct 2025
  • The 20th sanctions package, adopted 23 April 2026 with crypto measures effective 24 May 2026, imposed a complete ban on transactions between EU persons and any CASP or platform established in Russia, and an equivalent sectoral ban for Belarus, activating the EU's anti-circumvention tool against an entire jurisdiction for the first time. 23 Apr 2026
  • At its June 2026 Plenary, FATF made an initial determination that Bulgaria has substantially completed its AML/CFT action plan, including securing BO register accuracy and VASP/postal money operator market-entry controls, and now warrants an on-site assessment before removal from the increased monitoring list. 19 Jun 2026
  • Commission Delegated Regulation (EU) 2026/83 added Bolivia and the British Virgin Islands to the EU high-risk third country AML/CFT list while delisting six African jurisdictions following FATF's June/October 2025 Plenary decisions. 4 Dec 2025

Sanctions changes

  • Russia added to the EU list of high-risk third countries for AML/CFT via Commission Delegated Regulation (EU) 2026/46, following a technical assessment of countries with suspended FATF membership. 3 Dec 2025
  • The EU's 19th Russia sanctions package (23 Oct 2025) imposed a full transaction ban on Rosneft and Gazprom Neft, a Russian LNG import ban from 1 Jan 2027, transaction bans on 5 additional Russian banks and 8 third-country financial operators, and first-ever crypto-sector sanctions (A7A5 stablecoin ecosystem). 23 Oct 2025
  • The EU's 20th sanctions package (23 Apr 2026) introduced a full maritime services ban for Russian crude oil, listed 43 additional shadow-fleet vessels (reaching 640 total), and imposed a sector-wide transaction ban on Russian/Belarusian CASPs, effective 24 May 2026. 23 Apr 2026
  • Council Regulation (EU) 2025/2618 (18 Dec 2025) sanctioned 41 further shadow-fleet vessels; the Council separately renewed the core territorial-integrity sanctions regime for six months to 31 July 2026 and the Crimea/Sevastopol regime to 23 June 2026, requiring periodic re-authorisation votes that create renewal-cliff risk. 18 Dec 2025

Regulatory horizon (register)

  • AMLR (Reg 2024/1624) becomes directly applicable EU-wide
  • AMLA's first harmonised selection of 40 directly-supervised entities
  • 6AMLD Member State transposition deadlines complete
  • FATF October 2026 Plenary: Bulgaria on-site verification outcome
  • AMLA full staffing and fee-based funding model matures

Active schemes

  • [CRITICAL] Ruble-backed stablecoin (A7A5/Grinex) sanctions-evasion architecture
  • [HIGH] EU beneficial-ownership register opacity post-Sovim rollback
  • [CRITICAL] DPRK IT-worker crypto proliferation-financing network (EU node)
  • Divergent CASP/MiCA supervision enabling jurisdiction shopping
Sources
  1. European Commission / AMLA
  2. Council of the European Union
  3. European Commission
  4. Council of the European Union
  5. FATF
  6. European e-Justice Portal (European Commission)
  7. OCCRP
  8. Chainalysis
  9. Council of the European Union
  10. TRM Labs
  11. HM Treasury (UK)
Coverage gaps
Since the November 2022 CJEU Sovim/WM ruling, the EU's BORIS…
Since the November 2022 CJEU Sovim/WM ruling, the EU's BORIS beneficial-ownership interconnection system cannot provide public access to national BO registers, reversing a core 5AMLD transparency tool relied on by investigators and civil society across the bloc.
A June 2026 Council document confirms that reciprocal exchan…
A June 2026 Council document confirms that reciprocal exchange of operational information between Europol and AMLA is currently not foreseen, despite both bodies sitting at the centre of the EU's financial-crime and money-laundering response architecture.
MiCA's single-passport model combined with divergent nationa…
MiCA's single-passport model combined with divergent national AML/CFT scrutiny at CASP authorisation has produced 'jurisdiction shopping' concerns publicly raised by France's AMF, Austria's FMA and Italy's CONSOB, while the EBA documented a 2.5-fold rise in authorised CASPs (2022-2024) alongside persistent AML control weaknesses.
Conflict-finance/extractive-industry integrity (D4) coverage…
Conflict-finance/extractive-industry integrity (D4) coverage specific to EEA/EU-bloc architecture is comparatively thin in this baseline relative to sanctions (D1) and crypto (D5) coverage; available sourcing centred on Russia-energy sanctions (oil price cap, LNG ban) rather than dedicated EU conflict-minerals or extractive-corruption enforcement actions within the 18-month window.

Evidence

Confidence-tiered claims

No structured claims published for this jurisdiction yet.